Share on XShare on LinkedInShare on Telegram
Web3 Security

Proof of Reserves Audit: How It Works and Who Needs It

Proof of reserves audits verify a crypto platform holds enough assets to cover customer liabilities, using Merkle trees or zk-proofs to confirm solvency without exposing individual balances. Learn how proof of reserves works, what it can't detect (like hidden liabilities or window dressing), and why exchanges, stablecoin issuers, and custodians rely on it for transparency in 2026.

Author
QuillAudits Team
August 27, 2026
Proof of Reserves Audit: How It Works and Who Needs It
Share on XShare on LinkedInShare on Telegram

Proof of reserves is a way for a custodian to demonstrate that it actually holds the assets it owes its users. A proper proof of reserves audit examines two sides of the equation: the assets the platform controls on-chain and the liabilities it owes to customers. If a report only shows the assets and ignores the liabilities, it doesn't prove solvency. It only tells half the story.

Here's how proof of reserves works, what it can and cannot prove, and which platforms benefit most from it.

What proof of reserves actually proves

Proof of reserves became widely adopted after the collapse of FTX in 2022, when it became clear that billions of dollars in customer funds were simply missing.

The idea is straightforward. An exchange, custodian, or token issuer provides cryptographic evidence that the assets it holds are sufficient to cover what it owes its users.

When implemented correctly, proof of reserves answers one question.

Do the assets under the platform's control fully cover its liabilities?

It doesn't measure profitability, business performance, or operational health. Its purpose is much narrower. It verifies that customer assets are backed one-to-one.

How it works, step by step

A proof of reserves process has two equally important parts.

The first is the proof of assets.

The platform demonstrates that it controls the wallets it claims to own. This is typically done by signing a message with the private keys for those addresses or performing a specific on-chain transaction that proves ownership. Once ownership is confirmed, anyone can verify the wallet balances directly on the blockchain.

The second is the proof of liabilities.

This is usually the more challenging part because the platform needs to prove what it owes its users without exposing individual account balances.

The most common approach is to use a Merkle tree.

Each customer's balance becomes a leaf in the tree, and those leaves are combined through hashing into a single Merkle root. That root is then published publicly. Every user can verify that their own balance is included by using a Merkle proof, without revealing the balances of anyone else.

The final step is comparing the two.

If the platform's total assets are equal to or greater than its total liabilities, it can be considered solvent at the time the snapshot was taken.

Many platforms also use an independent third party to verify wallet ownership and validate the Merkle root so users don't have to rely solely on the platform's claims.

What it does not prove

This is where proof of reserves is often misunderstood.

It has real value, but it also has clear limitations.

First, it's only a snapshot.

It reflects solvency at a single point in time. A platform could temporarily borrow assets before the snapshot is taken and return them afterward, a practice commonly known as window dressing. More frequent or unannounced checks make this harder, but they don't eliminate the possibility entirely.

Proof of reserves also doesn't detect hidden liabilities.

If a platform owes money through off-chain loans or other obligations that aren't included in the Merkle tree, those liabilities won't appear in the report.

Finally, proving control of a wallet doesn't necessarily prove exclusive ownership.

Shared custody arrangements or borrowed assets can make the reserve position appear stronger than it really is.

For that reason, proof of reserves should be viewed as a strong, verifiable indicator of solvency, not as a guarantee that every financial risk has been eliminated.

Attestation vs a full audit

These two terms are often used interchangeably, but they refer to different types of reviews.

proof of reserves attestation is a point-in-time cryptographic verification that compares a platform's assets with its liabilities.

full financial audit, conducted by an accounting firm, is much broader. It examines a company's financial records, accounting practices, and operations over an extended period rather than at a single moment.

Proof of reserves is faster, more transparent, and designed specifically for crypto. A financial audit provides a much wider view of the business. The strongest custodians typically use both because each serves a different purpose.

Where zk-proofs come in

More platforms are now adopting zero-knowledge proofs, particularly zk-SNARKs, to strengthen proof of reserves.

Instead of revealing information about customer balances or the size of the user base, these systems allow a platform to prove that it is solvent without exposing sensitive data.

Compared to a traditional Merkle tree approach, zero-knowledge proofs offer stronger privacy while preserving verifiability. That's one of the reasons they're becoming the preferred direction for larger custodians and exchanges in 2026.

Who needs a proof of reserves audit

Type of platform

Why they need it

Centralized exchanges

They hold customer funds directly, so proving solvency is essential for user trust.

Stablecoin issuers

Every token represents a promise that it's backed one-to-one by reserves.

Wrapped and bridged token issuers

The value of the wrapped asset depends entirely on the reserves behind it.

Custodians and CeFi lenders

They safeguard and manage client assets, making transparency critical.

RWA token issuers

Their tokens represent real-world assets, so users need confidence that those assets actually exist.

The general rule is straightforward.

If your platform holds assets on behalf of users, or issues a token that's supposed to be backed by reserves, proof of reserves is worth considering.

After the failures the industry has experienced over the past few years, users increasingly expect verifiable proof instead of simple assurances. Saying "trust us" is no longer enough.

Conclusion

Proof of reserves has become one of the most important transparency tools in crypto, but it's only effective when it's implemented completely. Verifying assets without accounting for liabilities doesn't prove solvency, and a single snapshot can't replace ongoing oversight. The platforms that inspire the most confidence are the ones that combine verifiable proof of reserves with regular attestations, independent reviews, and clear communication about what those reports do and don't guarantee.

Contents

Tell Us About Your Project
Subscribe to Newsletter
hashing bits image
Loading...
Loading...
cta-bg

WE SECURE EVERYTHING YOU BUILD.

From day-zero risk mapping to exchange-ready audits — QuillAudits helps projects grow with confidence. Smart contracts, dApps, infrastructure, compliance — secured end-to-end.

QuillAudits Logo


ISO 27001Circle Alliance Program
Uniswap FoundationAethiropt-collectivePolygon SPNBNB Chain Kickstart

All Rights Reserved. © 2026. QuillAudits - LLC